Junglewise Threat Intelligence

CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability

CVE-2020-0601 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2021-11-03

Technologies: go (Go), Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows Server 2019. Vendors: Go, Microsoft.

Executive brief

A spoofing vulnerability exists in the Windows CryptoAPI (Crypt32.dll) due to improper validation of Elliptic Curve Cryptography (ECC) certificates. Attackers can exploit this to sign malicious executables with spoofed certificates or conduct man-in-the-middle attacks to decrypt confidential information. The vulnerability is also known as 'CurveBall'.

Affected products

  • Microsoft Windows 10 1607, 1709, 1803, 1809, 1903, 1909, 1507
  • Microsoft Windows Server 2016 - , 1803, 1903, 1909
  • Microsoft Windows Server 2019 -
  • Golang Go 1.12 to 1.12.16, 1.13 to 1.13.7

Timeline

  • 2020-01-14: advisory: MSRC advisory published (based on CVE ID year and typical patch cycle)
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats